
AI assistants are picking up a new trick: add-ons. Instead of one general chatbot, you can now bolt on small packaged capabilities – “skills”, plugins, connectors – that teach the assistant a specific job. They install in seconds, often with a single command, and public collections of them are already online. One community repository on GitHub gathers plugins and skills for Claude Code for anyone to download.
The productivity pitch is real. Security firm Snyk’s write-up on Claude Skills for finance and quantitative work argues these add-ons take routine analysis off a specialist’s plate, and it puts security best practice in the same breath. That pairing is the part worth copying. Meanwhile OpenAI has opened its upgraded ChatGPT task scheduling tool to free accounts, and paid accounts can now set prompts to trigger when something happens in Gmail, Slack or GitHub.
Read that last part again from a business owner’s seat. An AI tool watching your inbox and your team chat is an AI tool holding a key to two of your most sensitive systems. Nothing has gone wrong here – there is no breach and no dodgy add-on in the news. But the shape of the risk is familiar. This is the software supply chain problem, the same one as browser extensions and app store plugins, arriving through a channel most small businesses have no process for.
Four things worth sorting out before the first one lands on a staff laptop:
- Decide who is allowed to install AI add-ons and connect them to work accounts. “Anyone” is a decision too.
- Prefer add-ons from the vendor or a known publisher over a copy someone found online.
- Check what each connector actually asks for. Read-only access to one mailbox is not the same as full access to everything.
- Keep a list of what is installed and where. If a tool turns out to be a problem, you want to know in minutes who has it.
None of this has to slow your team down. It just has to happen before, rather than after.
Worried this affects your business? Get a free 15-minute IT check – call Trends IT on 0485 011 911 or visit /contact/.
